| Package | Version | Risk Score | Verdict | Published ↓ | Checks Triggered |
|---|---|---|---|---|---|
| goldenmatch-embed | 0.1.0 |
5.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| AOT-biomaps | 2.9.731 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionGit Repository History+1 |
| cydeai-client | 0.1.1 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionMaintainer History |
| braintoken-downloader | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| auto-rotate | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionGit Repository HistoryMaintainer History |
| pharnoss | 0.2.0 |
4.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionMaintainer History |
| BharatFinTrack | 0.3.1 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| amber-codon-scanner | 0.1.1 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| ag2 | 0.13.3 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionTyposquatting+1 |
| agent-os-server | 0.5.10 |
4.0
|
suspicious | 05 Jun 2026 | Suspicious Page LinksMaintainer History |
| hydros-agent-sdk | 0.1.4 |
6.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| eigh-cuda120 | 0.3.12 |
5.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| torch-proj-r14 | — |
0.0
|
error | 05 Jun 2026 | — |
| torch-proj-r15 | — |
0.0
|
error | 05 Jun 2026 | — |
| act-tester | 0.4.0 |
6.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| hydros-agent-sdk-preview-curryzxh | 0.1.4.dev1 |
6.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| dgsolve | 0.1.0a0 |
6.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| pytest-api-contract | 0.3.0 |
6.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| test-report-dashboard | 0.3.0 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| amazon-bedrock-haystack | 6.11.0 |
6.0
|
suspicious | 05 Jun 2026 | Code ObfuscationCredential HarvestingMaintainer History |
| fhi-decaf | 1.0.6 |
4.0
|
suspicious | 05 Jun 2026 | Suspicious Page LinksMaintainer History |
| agent-roi-tracker | 0.1.1 |
4.0
|
safe | 05 Jun 2026 | Suspicious Page LinksGit Repository HistoryMaintainer History |
| pyrtipc | 0.0.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| rein-openhands | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| kavach-mcp | 0.1.1 |
4.0
|
safe | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| TM1py | 2.3.0 |
4.0
|
safe | 05 Jun 2026 | Outbound Network CallsTyposquattingMaintainer History |
| PeakPo | 7.10.12 |
5.0
|
suspicious | 05 Jun 2026 | Code ObfuscationMaintainer History |
| agentflow-client | 1.5.0 |
2.0
|
safe | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| agentflow-runtime | 1.5.0 |
5.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |
| torch-proj-r09 | — |
0.0
|
error | 05 Jun 2026 | — |
| torch-proj-r10 | — |
0.0
|
error | 05 Jun 2026 | — |
| torch-proj-r11 | — |
0.0
|
error | 05 Jun 2026 | — |
| torch-proj-r12 | — |
0.0
|
error | 05 Jun 2026 | — |
| loom-engine-rpg | 2.3.0 |
5.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| coding-agent-roi | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Suspicious Page LinksGit Repository HistoryMaintainer History |
| test-witty | 0.1.0 |
5.0
|
suspicious | 05 Jun 2026 | Shell / Subprocess ExecutionSuspicious Page LinksGit Repository HistoryMaintainer History |
| alibabacloud-apig20240327 | 7.0.5 |
4.0
|
safe | 05 Jun 2026 | Code ObfuscationSuspicious Page LinksMaintainer History |
| khadee-eda | 1.0.0 |
6.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| autoplay-setup | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsShell / Subprocess ExecutionMaintainer History |
| actaclad-agentguard | 1.2.0 |
4.0
|
suspicious | 05 Jun 2026 | Maintainer History |
| secure-sandbox | 0.0.1 |
9.0
|
malicious | 05 Jun 2026 | Code ObfuscationShell / Subprocess ExecutionCredential HarvestingRegistered Email Domain+2 |
| torch-proj-r01 | — |
0.0
|
error | 05 Jun 2026 | — |
| torch-proj-r02 | — |
0.0
|
error | 05 Jun 2026 | — |
| apex-dispatch-api-client | 0.7.2 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| torch-proj-r16 | — |
0.0
|
error | 05 Jun 2026 | — |
| agentx-security-sdk | 0.2.11 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsGit Repository HistoryMaintainer History |
| FunKitPy | 0.1.0 |
4.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| sccircuits | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Git Repository HistoryMaintainer History |
| preship | 0.1.0 |
6.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsCode ObfuscationShell / Subprocess ExecutionMaintainer History |
| aias-common | 1.15.0 |
4.0
|
suspicious | 05 Jun 2026 | Outbound Network CallsMaintainer History |